~ ZHPDiag v2015.11.25.174 Par Nicolas Coolman (2015/11/25) ~ Démarré par Olivier (Administrator) (2015/11/27 23:06:46) ~ Site: http://www.nicolascoolman.fr ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ Etat de la version: Version OK ~ Mode: Scanner ~ Rapport: C:\Users\Olivier\Desktop\ZHPDiag.txt ~ Rapport: C:\Users\Olivier\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ Démarrage du système: Normal (Normal boot) Windows 10 Pro, 64-bit (Build 10240) ---\\ Navigateurs Internet (3) - 0s GCIE: Google Chrome v46.0.2490.86 MFIE: Mozilla Firefox 40.0.3 (x86 fr) v40.0.3 MSIE: Internet Explorer v11.0.10240.16590 ---\\ Informations sur les produits Windows (8) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK ~ Windows(R) Operating System, VOLUME_MAK channel Windows ID Activation : OK ~ Windows Partial Key : 6MT6Y Windows License : OK ~ Windows Remaining Initializations Number : 1001 Windows Automatic Updates : OK ---\\ Logiciels de protection (2) - 1s Malwarebytes Anti-Malware version 2.2.0.1024 Windows Defender (Activate) ---\\ Logiciels d'optimisation (1) - 2s CCleaner v5.12 ---\\ Surveillance de Logiciels (2) - 2s Adobe Flash Player 19 NPAPI Adobe Acrobat Reader DC - Français ---\\ Informations sur le système (6) - 0s ~ Operating System: Intel64 Family 6 Model 70 Stepping 1, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 16468.948 MB (84% free) System Restore: Activé (Enable) System drive C: has 33 GB () free of 113 GB ---\\ Mode de connexion au système (3) - 0s ~ Computer Name: ZOTAC ~ User Name: Olivier ~ Logged in as Administrator ---\\ Enumération des unités disques (3) - 0s ~ Drive C: has 33 GB free of 113 GB (System) ~ Drive F: has 349 GB free of 476 GB ~ Drive G: has 22 GB free of 29 GB ---\\ Etat du Centre de Sécurité Windows (7) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Recherche particulière de fichiers génériques (25) - 0s [MD5.F1CBCB7FA6F3B309639AA2D4EF74469C] - 28/08/2015 - (.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\Explorer.exe [4532304] © [MD5.5DED2A3F11AE916C8F2724947E736261] - 10/07/2015 - (.Microsoft Corporation - Processus hôte Windows (Rundll32).) -- C:\WINDOWS\System32\rundll32.exe [59392] © [MD5.7718A2A9B2BFB2C8E2BAEB03310CA3FD] - 28/08/2015 - (.Microsoft Corporation - Application de démarrage de Windows.) -- C:\WINDOWS\System32\Wininit.exe [290312] © [MD5.E5D86250453B33900666D92ED1A92ABE] - 17/09/2015 - (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\WINDOWS\System32\wininet.dll [2740224] © [MD5.A7C48B051A9C5D5054916DE5BEBBCA2D] - 05/11/2015 - (.Microsoft Corporation - Application d’ouverture de session Windows.) -- C:\WINDOWS\System32\Winlogon.exe [579072] © [MD5.ECB1943967424DFB96E03F6A098434EF] - 28/08/2015 - (.Microsoft Corporation - Bibliothèque de licences.) -- C:\WINDOWS\System32\sppcomapi.dll [430592] © [MD5.C287D0E32771E3222A444DC527A29477] - 10/07/2015 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\System32\dnsapi.dll [680256] © [MD5.BB5BBD0E4D04047585E4ED0F07AA51E7] - 10/07/2015 - (.Microsoft Corporation - DNS DLL de l’API Client.) -- C:\WINDOWS\Syswow64\dnsapi.dll [534064] © [MD5.8C795953726C7D2DE72CE4748208C5ED] - 10/07/2015 - (.Microsoft Corporation - DLL client de l’API uilisateur de Windows m.) -- C:\WINDOWS\System32\fr-FR\user32.dll.mui [20480] © [MD5.A3D96563BF46FC8A0E5756B796127D14] - 05/11/2015 - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) -- C:\WINDOWS\System32\drivers\AFD.sys [577888] © [MD5.8921DF6060DB5C7700AA48CB12E9EA08] - 10/07/2015 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\WINDOWS\System32\drivers\atapi.sys [28512] © [MD5.F2829DC6D292DCAC5029893BB2E9FEE3] - 10/07/2015 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\WINDOWS\System32\drivers\Cdfs.sys [92672] © [MD5.CA160E02F35A61C6F5C681FB4669C519] - 10/07/2015 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\WINDOWS\System32\drivers\Cdrom.sys [174080] © [MD5.25435407D97419627F4B10653433BF2B] - 10/07/2015 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\WINDOWS\System32\drivers\DfsC.sys [138240] © [MD5.C277A49F8A8295840DEBC9240B75A282] - 10/07/2015 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\WINDOWS\System32\drivers\HDAudBus.sys [80896] © [MD5.D4CDEE4A62BDFFF6E8558A9552148EA7] - 10/07/2015 - (.Microsoft Corporation - Pilote de port i8042.) -- C:\WINDOWS\System32\drivers\i8042prt.sys [114688] © [MD5.5D3744E6FDEC1A6FB3FA9B1DD4AF0694] - 10/07/2015 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\System32\drivers\IpNat.sys [143360] © [MD5.1DF2C5FD2710A13B07E663A12F0E0EEA] - 10/07/2015 - (.Microsoft Corporation - Minirdr SMB Windows NT.) -- C:\WINDOWS\System32\drivers\MRxSmb.sys [415232] © [MD5.F0D791348AD254360CC3C3E501CCB745] - 10/07/2015 - (.Microsoft Corporation - MBT Transport driver.) -- C:\WINDOWS\System32\drivers\netBT.sys [273408] © [MD5.466EC5659C02ED53DBD47DC1BC2B8086] - 28/08/2015 - (.Microsoft Corporation - Pilote du système de fichiers NT.) -- C:\WINDOWS\System32\drivers\ntfs.sys [2116448] © [MD5.38F1AE32339731F6E5A7281AE8042545] - 10/07/2015 - (.Microsoft Corporation - Pilote de port parallèle.) -- C:\WINDOWS\System32\drivers\Parport.sys [96768] © [MD5.CA60F6C03611AF1710BC903ED9F566FB] - 10/07/2015 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\WINDOWS\System32\drivers\Rasl2tp.sys [104960] © [MD5.A32AED8C644734B283A7C9D08D76064D] - 10/07/2015 - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RD.) -- C:\WINDOWS\System32\drivers\rdpdr.sys [176128] © [MD5.D42AC03ACF9CA67693D1D9BB4D2A0BC8] - 05/11/2015 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\WINDOWS\System32\drivers\tdx.sys [116064] © [MD5.823A237D871CD652C6BFD47BECB6810A] - 10/07/2015 - (.Microsoft Corporation - Pilote de cliché instantané du volume.) -- C:\WINDOWS\System32\drivers\volsnap.sys [378720] © ---\\ Logiciels installés (137) - 6s O42 - Logiciel: AC3Filter 1.63b - (.Alexander Vigovsky.) [HKLM][64Bits] -- AC3Filter_is1 © O42 - Logiciel: Adobe Acrobat Reader DC - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AC0F074E4100} © O42 - Logiciel: Adobe Flash Player 19 NPAPI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player NPAPI © O42 - Logiciel: Adobe Refresh Manager - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-0804-1033-1959-001824161310} © O42 - Logiciel: Ant Renamer - (.Ant Software.) [HKLM][64Bits] -- Ant Renamer 2_is1 © O42 - Logiciel: Ashampoo WinOptimizer 12 - (.Ashampoo GmbH & Co. KG.) [HKLM][64Bits] -- {4209F371-15B6-1CE4-15F7-A7BA46F431E3}_is1 © O42 - Logiciel: Audacity 2.1.0 - (.Audacity Team.) [HKLM][64Bits] -- Audacity_is1 © O42 - Logiciel: AviSynth 2.6 - (.GPL Public release..) [HKLM][64Bits] -- AviSynth O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner © O42 - Logiciel: Ciel Compta 19.0 - (.Ciel.) [HKLM][64Bits] -- {041F6B70-807E-4B21-ADEF-436E522596F4} © O42 - Logiciel: Ciel Gestion commerciale 19.0 - (.Ciel.) [HKLM][64Bits] -- {D2A9926B-E449-4894-B9A4-DF2C43712DDB} © O42 - Logiciel: Configuration DivX - (.DivX, LLC.) [HKLM][64Bits] -- DivX Setup © O42 - Logiciel: Data On The Run Installer - (...) [HKLM][64Bits] -- Data On The Run Installer O42 - Logiciel: Data On The Run Sync - (.Biomobility, LLC.) [HKLM][64Bits] -- {FDA3CD1B-947B-4A28-A885-28D8F8CC4554} O42 - Logiciel: dBpoweramp - (.Illustrate.) [HKLM][64Bits] -- dBpoweramp © O42 - Logiciel: dBpoweramp DSP Effects - (.Illustrate.) [HKLM][64Bits] -- dBpoweramp DSP Effects © O42 - Logiciel: DirectVobSub (remove only) - (...) [HKLM][64Bits] -- DirectVobSub O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKLM][64Bits] -- Dropbox © O42 - Logiciel: Dropbox Update Helper - (.Dropbox, Inc..) [HKLM][64Bits] -- {099218A5-A723-43DC-8DB5-6173656A1E94} © O42 - Logiciel: DVD Shrink 3.2 - (.DVD Shrink.) [HKLM][64Bits] -- DVD Shrink_is1 © O42 - Logiciel: eM Client - (.eM Client Inc..) [HKLM][64Bits] -- {F3D4FF28-2C9E-45E5-B983-CE8BF449ECEC} O42 - Logiciel: Emergency Download Driver - (.Microsoft.) [HKLM][64Bits] -- {3F0F5AB4-C9CE-4226-8393-E9CFF8369D9D} © O42 - Logiciel: EPSON Scan - (.Seiko Epson Corporation.) [HKLM][64Bits] -- EPSON Scanner © O42 - Logiciel: EPSON SX535WD Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM][64Bits] -- EPSON SX535WD Series © O42 - Logiciel: EpsonNet Print - (.SEIKO EPSON CORPORATION.) [HKLM][64Bits] -- {3E31400D-274E-4647-916C-2CACC3741799} © O42 - Logiciel: FairUse Wizard 3D - (.FairUse Wizard.) [HKLM][64Bits] -- FairUse Wizard 3D O42 - Logiciel: Fintek USBCharger - (.Fintek Inc..) [HKLM][64Bits] -- {F844402B-53FF-4F06-9192-BDBF7FB98EB3} O42 - Logiciel: Flash Update Installer - (.Microsoft.) [HKLM][64Bits] -- {CCAC332A-E7B4-457E-B41C-D92F6CBB3111} © O42 - Logiciel: Flash Video Downloader 0.1 - (.http://www.flashvideodownloader.org.) [HKLM][64Bits] -- Flash Video Downloader_is1 O42 - Logiciel: foobar2000 v1.3.8 - (.Peter Pawlowski.) [HKLM][64Bits] -- foobar2000 © O42 - Logiciel: FormatFactory 3.8.0.0 - (.Free Time.) [HKLM][64Bits] -- FormatFactory © O42 - Logiciel: Fuse Installer - (.Nokia.) [HKLM][64Bits] -- {3D2A20D3-1EAD-480B-8DB7-DD97D821A272} © O42 - Logiciel: Gestionnaire pour appareils Windows Mobile - (.Microsoft Corporation.) [HKLM][64Bits] -- {626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B} © O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome © O42 - Logiciel: Google Earth Pro - (.Google.) [HKLM][64Bits] -- {5BAA8884-F661-464B-B5B2-5C6C632BFC21} © O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} © O42 - Logiciel: HandBrake 0.10.2 - (...) [HKLM][64Bits] -- HandBrake O42 - Logiciel: IE Download Helper - (.IE Download Helper.) [HKLM][64Bits] -- {424E1389-2414-4394-9476-5D26316F291F} O42 - Logiciel: Intel(R) Cloud Access Manager - (.Intel Corporation.) [HKLM][64Bits] -- {48500E3A-90D9-4FA4-8DA9-7BFB77A5A2AE} © O42 - Logiciel: Intel(R) Driver Update Utility 2.0 - (.Intel.) [HKLM][64Bits] -- {59DB38EB-F864-4E10-841D-38CFBCF864B0} © O42 - Logiciel: Intel(R) Manageability Engine Firmware Recovery Agent - (.Intel Corporation.) [HKLM][64Bits] -- {0EC7F9CC-4741-45AE-9F55-6E9343F726F5} © O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A} © O42 - Logiciel: Intel(R) PRO/Wireless Driver - (.Intel Corporation.) [HKLM][64Bits] -- {021da516-b5d9-40cd-9ade-6427d40fe1e4} © O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} © O42 - Logiciel: Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology(patch version - (.Intel Corporation.) [HKLM][64Bits] -- {302600C1-6BDF-4FD1-1307-148929CC1385} © O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140} © O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {93F692D4-0C4D-4EED-9BFE-657C1D5959FE} © O42 - Logiciel: Intel® Driver Update Utility - (.Intel.) [HKLM][64Bits] -- {8409c4f7-2340-4933-a304-5d37db4fb48b} © O42 - Logiciel: Intel® PROSet/Wireless WiFi Software - (.Intel Corporation.) [HKLM][64Bits] -- {AAE0AC3F-17BF-48CD-96CE-4F19169E94B0} © O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {B5E06417-A4AC-4225-B36E-7E34C91616E7} © O42 - Logiciel: Java 8 Update 40 (64-bit) - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86418040F0} © O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} © O42 - Logiciel: K-Lite Mega Codec Pack 10.8.0 - (...) [HKLM][64Bits] -- KLiteCodecPack_is1 O42 - Logiciel: KMSpico - (...) [HKLM][64Bits] -- {8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>HackTool.KMSpico O42 - Logiciel: LAME v3.99.3 (for Windows) - (...) [HKLM][64Bits] -- LAME_is1 O42 - Logiciel: LAV Filters 0.60.1 - (.Hendrik Leppkes.) [HKLM][64Bits] -- lavfilters_is1 © O42 - Logiciel: Logiciel Intel® PROSet/Wireless - (.Intel Corporation.) [HKLM][64Bits] -- {a9888f41-68ae-43df-bd7d-d93405a44106} © O42 - Logiciel: Lumia UEFI Blue Driver - (.Microsoft.) [HKLM][64Bits] -- {9D2A75FE-8CE1-4297-AEC1-A097D47BACE9} © O42 - Logiciel: m4ng - (...) [HKLM][64Bits] -- m4ng O42 - Logiciel: m4ng Codec Pack - (...) [HKLM][64Bits] -- m4ng Codec Pack O42 - Logiciel: Malwarebytes Anti-Malware version 2.2.0.1024 - (.Malwarebytes.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1 © O42 - Logiciel: MediaInfo 0.7.35 - (.MediaArea.net.) [HKLM][64Bits] -- MediaInfo © O42 - Logiciel: Medieval CUE Splitter - (.Medieval Software.) [HKLM][64Bits] -- {B96D2269-568B-4CBF-9332-12FAE8B158F7} © O42 - Logiciel: Microsoft Access MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0015-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM][64Bits] -- {5AF3560C-09BA-426F-BFA0-FEF0A94A9D8B} © O42 - Logiciel: Microsoft Corporation - (.Microsoft Corporation.) [HKLM][64Bits] -- {A1CF7B76-682D-4547-AA96-11B659A2CEAC} © O42 - Logiciel: Microsoft DCF MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0090-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Excel MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0016-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Groove MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00BA-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft InfoPath MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0044-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft LifeCam - (.Microsoft Corporation.) [HKLM][64Bits] -- {8EC9E7BB-2443-49B1-8476-490EBF932C2E} © O42 - Logiciel: Microsoft Lync MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft OneNote MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-00A1-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Outlook MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001A-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft PowerPoint MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0018-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Publisher MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-0019-040C-1000-0000000FF1CE} © O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} © O42 - Logiciel: Microsoft Sync Framework 2.0 Core Components (x86) ENU - (.Microsoft Corporation.) [HKLM][64Bits] -- {FF63121D-91C6-42CC-B341-F1AA729728E7} © O42 - Logiciel: Microsoft Sync Framework 2.0 Provider Services (x86) ENU - (.Microsoft Corporation.) [HKLM][64Bits] -- {D3A80508-CD83-4CA3-8671-914A1BC78B61} © O42 - Logiciel: Microsoft Word MUI (French) 2013 - (.Microsoft Corporation.) [HKLM][64Bits] -- {90150000-001B-040C-1000-0000000FF1CE} © O42 - Logiciel: MKVtoolnix 4.4.0 - (.Moritz Bunkus.) [HKLM][64Bits] -- MKVtoolnix © O42 - Logiciel: Monkey's Audio - (...) [HKLM][64Bits] -- Monkey's Audio_is1 O42 - Logiciel: Mozilla Firefox 40.0.3 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 40.0.3 (x86 fr) © O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService © O42 - Logiciel: Mp3tag v2.72 - (.Florian Heidenreich.) [HKLM][64Bits] -- Mp3tag © O42 - Logiciel: Nitro Pro 10 - (.Nitro.) [HKLM][64Bits] -- {BC1E28B9-90FB-46FE-84D0-579DDF9F5485} © O42 - Logiciel: Nokia Connectivity Cable Driver - (.Nokia.) [HKLM][64Bits] -- {D4BF151C-70A8-4CE2-906F-4173A575BAD9} © O42 - Logiciel: Nokia Software Recovery Tool 6.0.3 - (.Microsoft.) [HKLM][64Bits] -- {214BC75F-885A-409A-9680-CC73E6E69F00} © O42 - Logiciel: Nokia Software Recovery Tool 6.0.3 - (.Microsoft.) [HKLM][64Bits] -- {83561e18-2d60-482c-a5ed-92f41b711a7c} © O42 - Logiciel: Nuvoton SIO CIR Device Driver - (.Nuvoton Technology Corp..) [HKLM][64Bits] -- {2FAECEAF-0EBE-48FF-B60A-B4577C0EFDAB} O42 - Logiciel: OVH MoM - (...) [HKLM][64Bits] -- OVH MoM O42 - Logiciel: PDFCreator - (.pdfforge.) [HKLM][64Bits] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D} © O42 - Logiciel: PhotoFiltre 7 - (...) [HKCU][64Bits] -- PhotoFiltre 7 O42 - Logiciel: PowerISO - (.Power Software Ltd.) [HKLM][64Bits] -- PowerISO © O42 - Logiciel: PowerISO 6.2 - (.RePack by CUTA.) [HKLM][64Bits] -- {D13579F6-B7DF-44FF-98FF-389BE33E809D}_is1 O42 - Logiciel: Product API Installer - (.Microsoft.) [HKLM][64Bits] -- {1D0508E5-C1D7-40D7-BFE9-03D6BC09C220} © O42 - Logiciel: QGIS Wien 2.8.1 Wien - (.QGIS Development Team.) [HKLM][64Bits] -- QGIS Wien O42 - Logiciel: Realtek Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {5BC2B5AB-80DE-4E83-B8CF-426902051D0A} © O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476} © O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC} © O42 - Logiciel: Remove Empty Directories version 2.2 - (.Jonas John.) [HKLM][64Bits] -- {06F25DC8-71E2-44E2-805A-F15E15B51C74}_is1 O42 - Logiciel: Security Update for Skype for Business 2015 (KB3101496) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A94C74CC-7A1C-4D8F-A46A-8EB020C4D4DD} © O42 - Logiciel: Security Update for Skype for Business 2015 (KB3101496) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUS_{A94C74CC-7A1C-4D8F-A46A-8EB020C4D4DD} © O42 - Logiciel: Security Update for Skype for Business 2015 (KB3101496) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{A94C74CC-7A1C-4D8F-A46A-8EB020C4D4DD} © O42 - Logiciel: SlimDrivers - (.SlimWare Utilities, Inc..) [HKLM][64Bits] -- {5AD12E7A-D739-4451-9BD1-3610EC56D8F5} O42 - Logiciel: SyncToy 2.1 (x86) - (.Microsoft.) [HKLM][64Bits] -- {A066194B-DC8F-449A-8E0F-B57BDD3A2072} © O42 - Logiciel: Synology Assistant (remove only) - (...) [HKLM][64Bits] -- Synology Assistant O42 - Logiciel: Synology Cloud Station (remove only) - (.Synology, Inc..) [HKLM][64Bits] -- Synology Cloud Station O42 - Logiciel: TeamViewer 10 - (.TeamViewer.) [HKLM][64Bits] -- TeamViewer © O42 - Logiciel: tools-freebsd - (.VMware, Inc..) [HKLM][64Bits] -- {003BFBBD-6C67-419E-A24D-0DCAFC3A5249} © O42 - Logiciel: tools-linux - (.VMware, Inc..) [HKLM][64Bits] -- {D102611A-6466-4101-A51D-51069303AC65} © O42 - Logiciel: tools-netware - (.VMware, Inc..) [HKLM][64Bits] -- {197597A7-AD33-4898-9D8E-73066818B464} © O42 - Logiciel: tools-solaris - (.VMware, Inc..) [HKLM][64Bits] -- {AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4} © O42 - Logiciel: tools-windows - (.VMware, Inc..) [HKLM][64Bits] -- {FFD9383C-01D5-4897-A954-43AF599AED30} © O42 - Logiciel: tools-winPre2k - (.VMware, Inc..) [HKLM][64Bits] -- {AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D} © O42 - Logiciel: TreeSize Free V3.3.2 - (.JAM Software.) [HKLM][64Bits] -- TreeSize Free_is1 © O42 - Logiciel: TubeDigger 5.4.3 - (.TubeDigger.) [HKLM][64Bits] -- {1E3745C1-674D-4B2E-B8F7-3F4088950ED7}_is1 © O42 - Logiciel: UnderCover10 2.03 - (.Wicked & Wild Inc..) [HKLM][64Bits] -- UnderCover10_is1 © O42 - Logiciel: Update for Skype for Business 2015 (KB2889853) 64-Bit Edition - (.Microsoft.) [HKLM][64Bits] -- {90150000-012B-040C-1000-0000000FF1CE}_Office15.PROPLUS_{DD51BA84-F589-4939-B5FE-5538B3DCC12E} © O42 - Logiciel: USB Serial Port Driver - (.Microsoft.) [HKLM][64Bits] -- {FE11883D-EA67-473C-BDD1-8D6B6DFCBEAC} © O42 - Logiciel: VC80CRTRedist - 8.0.50727.6195 - (.DivX, Inc.) [HKLM][64Bits] -- {933B4015-4618-4716-A828-5289FC03165F} © O42 - Logiciel: Video Converter Ultimate 7.8.9.20150724 - (.l-rePack®.) [HKLM][64Bits] -- Video Converter Ultimate_is1 O42 - Logiciel: VirtualDub 1.9.6 Fr - (.Trad-Fr.) [HKLM][64Bits] -- {1FF7993C-23B1-4C91-B1F6-09D13C57A06A}_is1 © O42 - Logiciel: Visuel intégré - (.Druide informatique inc..) [HKLM][64Bits] -- {D6A48C7F-A0F8-46A5-A1ED-F45A62FE93BF} © O42 - Logiciel: VMware Workstation - (.VMware, Inc.) [HKLM][64Bits] -- VMware_Workstation © O42 - Logiciel: VMware Workstation - (.VMware, Inc..) [HKLM][64Bits] -- {0D94F75A-0EA6-4951-B3AF-B145FA9E05C6} © O42 - Logiciel: Windows Device Recovery Tool 3.1.2 - (.Microsoft.) [HKLM][64Bits] -- {9C1471ED-337C-4B7C-993D-6D5BC97A3E3C} © O42 - Logiciel: Windows Device Recovery Tool 3.1.2 - (.Microsoft.) [HKLM][64Bits] -- {9e156ead-3518-4112-999a-4188770fc8ad} © O42 - Logiciel: Windows Phone app for desktop - (.Microsoft Corporation.) [HKLM][64Bits] -- {639E54EE-95CA-4CAE-9779-6BA32D5EAF48} © O42 - Logiciel: WinRAR 5.11 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver © O42 - Logiciel: WinUsb CoInstallers - (.Microsoft.) [HKLM][64Bits] -- {9755918A-CDF8-4F1E-8453-6359CF1A330A} © O42 - Logiciel: WinUSB Compatible ID Drivers - (.Microsoft.) [HKLM][64Bits] -- {A4A0B236-6046-4CAB-8177-1EAF61112C75} © O42 - Logiciel: WinUSB Drivers ext - (.Microsoft.) [HKLM][64Bits] -- {B7F55FF1-607A-4E12-BF64-8770BC618D12} © O42 - Logiciel: WYSIWYG Web Builder 10 - (...) [HKLM][64Bits] -- WYSIWYG_Web_Builder_10 O42 - Logiciel: XnView 2.05 - (.Gougelet Pierre-e.) [HKLM][64Bits] -- XnView_is1 © O42 - Logiciel: XnView Shell Extension 3.4.0 - (.Gougelet Pierre-e.) [HKLM][64Bits] -- XnView Shell Extension_is1 © O42 - Logiciel: Xvid 1.2.2 final uninstall - (.Xvid team (Koepi).) [HKLM][64Bits] -- Xvid_is1 © ---\\ HKCU & HKLM Software Keys (170) - 6s HKLM\SOFTWARE\Wow6432Node\Adobe HKLM\SOFTWARE\Wow6432Node\Adobee HKLM\SOFTWARE\Wow6432Node\Apple Inc. HKLM\SOFTWARE\Wow6432Node\Ashampoo HKLM\SOFTWARE\Wow6432Node\AviSynth HKLM\SOFTWARE\Wow6432Node\Biomobility HKLM\SOFTWARE\Wow6432Node\BSAddins HKLM\SOFTWARE\Wow6432Node\Caphyon HKLM\SOFTWARE\Wow6432Node\CodeGear HKLM\SOFTWARE\Wow6432Node\CyberGhost HKLM\SOFTWARE\Wow6432Node\Cygwin HKLM\SOFTWARE\Wow6432Node\DirectShowFilters HKLM\SOFTWARE\Wow6432Node\DivX HKLM\SOFTWARE\Wow6432Node\Dropbox HKLM\SOFTWARE\Wow6432Node\DropboxUpdate HKLM\SOFTWARE\Wow6432Node\Druide informatique inc. HKLM\SOFTWARE\Wow6432Node\ee480a2b-b3ce-acd0-c1a7-bcdecce57714 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\EPSON HKLM\SOFTWARE\Wow6432Node\EpsonNet HKLM\SOFTWARE\Wow6432Node\FairUse Wizard HKLM\SOFTWARE\Wow6432Node\Fintek Inc. HKLM\SOFTWARE\Wow6432Node\Florian Heidenreich HKLM\SOFTWARE\Wow6432Node\foobar2000 HKLM\SOFTWARE\Wow6432Node\GNU HKLM\SOFTWARE\Wow6432Node\Google HKLM\SOFTWARE\Wow6432Node\HaaliMkx HKLM\SOFTWARE\Wow6432Node\IE Download Helper HKLM\SOFTWARE\Wow6432Node\InstallShield HKLM\SOFTWARE\Wow6432Node\Intel HKLM\SOFTWARE\Wow6432Node\IVT Corporation HKLM\SOFTWARE\Wow6432Node\JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos HKLM\SOFTWARE\Wow6432Node\KLCodecPack HKLM\SOFTWARE\Wow6432Node\Lame For Audacity HKLM\SOFTWARE\Wow6432Node\LAV HKLM\SOFTWARE\Wow6432Node\Likno Software HKLM\SOFTWARE\Wow6432Node\Macromedia HKLM\SOFTWARE\Wow6432Node\Mail.Ru HKLM\SOFTWARE\Wow6432Node\Malwarebytes' Anti-Malware HKLM\SOFTWARE\Wow6432Node\mkvmergeGUI HKLM\SOFTWARE\Wow6432Node\Mozilla HKLM\SOFTWARE\Wow6432Node\mozilla.org HKLM\SOFTWARE\Wow6432Node\MozillaPlugins HKLM\SOFTWARE\Wow6432Node\Nalpeiron HKLM\SOFTWARE\Wow6432Node\Nokia HKLM\SOFTWARE\Wow6432Node\Nokia Mobile Phones HKLM\SOFTWARE\Wow6432Node\Nuance HKLM\SOFTWARE\Wow6432Node\Nuvoton Technology Corp. HKLM\SOFTWARE\Wow6432Node\ODBC HKLM\SOFTWARE\Wow6432Node\OVH HKLM\SOFTWARE\Wow6432Node\PC Connectivity Solution HKLM\SOFTWARE\Wow6432Node\PCSuite HKLM\SOFTWARE\Wow6432Node\PIP =>Toolbar.Ask HKLM\SOFTWARE\Wow6432Node\PowerISO HKLM\SOFTWARE\Wow6432Node\PowerPivot HKLM\SOFTWARE\Wow6432Node\Realtek HKLM\SOFTWARE\Wow6432Node\Realtek Semiconductor Corp. HKLM\SOFTWARE\Wow6432Node\Sage HKLM\SOFTWARE\Wow6432Node\SEIKO EPSON CORPORATION HKLM\SOFTWARE\Wow6432Node\Skype HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities Inc HKLM\SOFTWARE\Wow6432Node\SlimWare Utilities, Inc. HKLM\SOFTWARE\Wow6432Node\SpoonInstall HKLM\SOFTWARE\Wow6432Node\TeamViewer HKLM\SOFTWARE\Wow6432Node\ThinPrint HKLM\SOFTWARE\Wow6432Node\Trad-FR HKLM\SOFTWARE\Wow6432Node\TubeDigger HKLM\SOFTWARE\Wow6432Node\VMware, Inc. HKLM\SOFTWARE\Wow6432Node\Volatile HKLM\SOFTWARE\Wow6432Node\WafCX HKLM\SOFTWARE\Wow6432Node\Wondershare HKLM\SOFTWARE\Wow6432Node\Wow6432Node HKLM\SOFTWARE\Wow6432Node\Xilisoft HKLM\SOFTWARE\Wow6432Node\XnView HKLM\SOFTWARE\Wow6432Node\RegisteredApplications HKCU\SOFTWARE\AC3Filter HKCU\SOFTWARE\Adobe HKCU\SOFTWARE\Aiseesoft Studio HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKCU\SOFTWARE\AppDataLow HKCU\SOFTWARE\Badger I.T. HKCU\SOFTWARE\Biomobility HKCU\SOFTWARE\BugSplat HKCU\SOFTWARE\Clubic HKCU\SOFTWARE\Cygwin HKCU\SOFTWARE\DivX HKCU\SOFTWARE\DivXNetworks HKCU\SOFTWARE\Dropbox HKCU\SOFTWARE\DropboxUpdate HKCU\SOFTWARE\Druide informatique inc. HKCU\SOFTWARE\DVD Decrypter HKCU\SOFTWARE\DVD Shrink HKCU\SOFTWARE\DVDFab HKCU\SOFTWARE\eM Client HKCU\SOFTWARE\EPSON HKCU\SOFTWARE\ERDAS HKCU\SOFTWARE\FairUse Wizard 2 HKCU\SOFTWARE\FairUseW HKCU\SOFTWARE\foobar2000 HKCU\SOFTWARE\Foxit Software HKCU\SOFTWARE\FreeTime HKCU\SOFTWARE\Freeware HKCU\SOFTWARE\FUW HKCU\SOFTWARE\Gabest HKCU\SOFTWARE\GNU HKCU\SOFTWARE\Google HKCU\SOFTWARE\gSyncit HKCU\SOFTWARE\Haali HKCU\SOFTWARE\Illustrate HKCU\SOFTWARE\IM Providers HKCU\SOFTWARE\Intel HKCU\SOFTWARE\IvoSoft HKCU\SOFTWARE\JAM Software HKCU\SOFTWARE\JavaSoft HKCU\SOFTWARE\labDV.com HKCU\SOFTWARE\LAV HKCU\SOFTWARE\m4ng HKCU\SOFTWARE\Macromedia HKCU\SOFTWARE\Mail.Ru HKCU\SOFTWARE\MainConcept HKCU\SOFTWARE\MakeMKV HKCU\SOFTWARE\Medieval HKCU\SOFTWARE\mkvmergeGUI HKCU\SOFTWARE\Monkey's Audio HKCU\SOFTWARE\MOVAVI HKCU\SOFTWARE\Mozilla HKCU\SOFTWARE\MozillaPlugins HKCU\SOFTWARE\MPC-HC HKCU\SOFTWARE\NetBox HKCU\SOFTWARE\Netscape HKCU\SOFTWARE\Nitro HKCU\SOFTWARE\Novell HKCU\SOFTWARE\ODBC HKCU\SOFTWARE\OVH HKCU\SOFTWARE\Pablo Software Solutions HKCU\SOFTWARE\PDF Architect 4 HKCU\SOFTWARE\pdfforge HKCU\SOFTWARE\PhotoFiltre 7 HKCU\SOFTWARE\Piriform HKCU\SOFTWARE\Pixart HKCU\SOFTWARE\PowerISO HKCU\SOFTWARE\QGIS HKCU\SOFTWARE\QtProject HKCU\SOFTWARE\Realtek HKCU\SOFTWARE\RegisteredApplications HKCU\SOFTWARE\Samsung HKCU\SOFTWARE\Skype HKCU\SOFTWARE\SlimWare Utilities Inc HKCU\SOFTWARE\SpoonInstall HKCU\SOFTWARE\SyncEngines HKCU\SOFTWARE\Synology HKCU\SOFTWARE\TeamViewer HKCU\SOFTWARE\telecharger-gratuit HKCU\SOFTWARE\Trolltech HKCU\SOFTWARE\TubeDigger HKCU\SOFTWARE\UltraDVD HKCU\SOFTWARE\VB and VBA Program Settings HKCU\SOFTWARE\VirtualDub.org HKCU\SOFTWARE\VMware, Inc. HKCU\SOFTWARE\WebApp HKCU\SOFTWARE\WinRAR HKCU\SOFTWARE\Wondershare HKCU\SOFTWARE\Wow6432Node HKCU\SOFTWARE\Xilisoft HKCU\SOFTWARE\ZebHelpProcess Helper HKCU\SOFTWARE\AppDataLow\Software HKCU\SOFTWARE\AppDataLow\Software\JavaSoft HKCU\SOFTWARE\AppDataLow\Software\Mail.Ru HKCU\SOFTWARE\AppDataLow\Software\ThinPrint ---\\ Liste des services NT non Microsoft et non désactivés (23) - 1s O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © O23 - Service: ADU Service (Nokia Software Recovery Tool) (ADUServiceNSRT) . (...) - C:\Program Files (x86)\Common Files\Microsoft\Care Suite\ADUService\ADUService.exe O23 - Service: CAM Service (CAMService) . (.Intel® Corporation - CAMService Module.) - C:\Program Files\Intel\CAM\bin\CAMService.exe © O23 - Service: Service Mise à jour Dropbox (dbupdate) (dbupdate) . (.Dropbox, Inc. - Dropbox Update.) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe © O23 - Service: EPSON V3 Service4(05) (EPSON_PM_RPCV4_05) . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE © O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe © O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation - igfxCUIService Module.) - C:\Windows\System32\igfxCUIService.exe © O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe © O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management (Intel(R) Wireless Bluetooth(R) 4.0 Radio Management) . (.Intel Corporation - Intel(R) Wireless Bluetooth(R) Radio Manage.) - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe © O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe © O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe © O23 - Service: (MBAMScheduler) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe © O23 - Service: (MBAMService) . (.Malwarebytes - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe © O23 - Service: NitroPDFDriverCreatorReadSpool10 (NitroDriverReadSpool10) . (.Nitro PDF Software - Nitro PDF Spool Service.) - C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe © O23 - Service: NitroUpdateService (NitroUpdateService) . (...) - C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe O23 - Service: Service KMSELDI (Service KMSELDI) . (.@ByELDI - Service_KMS.) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico O23 - Service: TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH - TeamViewer 10.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe © O23 - Service: UsbClientService (UsbClientService) . (...) - C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe O23 - Service: VMware Authorization Service (VMAuthdService) . (.VMware, Inc. - VMware Authorization Service.) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe © O23 - Service: VMware DHCP Service (VMnetDHCP) . (.VMware, Inc. - VMware VMnet DHCP service.) - C:\Windows\SysWOW64\vmnetdhcp.exe © O23 - Service: VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc. - VMware USB Arbitration Service.) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe © O23 - Service: VMware NAT Service (VMware NAT Service) . (.VMware, Inc. - VMware NAT Service.) - C:\Windows\SysWOW64\vmnat.exe © ---\\ Tâches planifiées en automatique (31) - 4s [MD5.B89A82FB10E98F2FDF51FA82C7366DD3] [APT] [Adobe Acrobat Update Task] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1067736] © [MD5.280A526E8111AC6A5BCC1A059E1E0340] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [269000] © [MD5.F1CE8A8107117151704BED2729CC0717] [APT] [AutoPico Daily Restart] (.@ByELDI.) -- C:\Program Files\KMSpico\AutoPico.exe [971968] =>HackTool.KMSpico [MD5.00000000000000000000000000000000] [APT] [BeneFit] (...) -- c:\programdata\{1e41b85d-d98d-d7db-1e41-1b85dd98e177}\em client v6 22313 0 happy 420-crd.exe (.not file.) [0] [MD5.5C35525CEBE7B59FAFA05D5E98D7EDEF] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [6602152] © [MD5.33BFEC2B102B196B62ABB9947C7D7E23] [APT] [DropboxUpdateTaskMachineCore] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048] © [MD5.33BFEC2B102B196B62ABB9947C7D7E23] [APT] [DropboxUpdateTaskMachineUA] (.Dropbox, Inc..) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048] © [MD5.2491BB82556C60CD7CA6A03F1EE43BEA] [APT] [eM Client Database Backup] (...) -- C:\Program Files (x86)\eM Client\DbBackup.exe [138024] [MD5.C6FF00DA1605982E616C03BE809FFE2D] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] © [MD5.C6FF00DA1605982E616C03BE809FFE2D] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200] © [MD5.76328EEAEDC5203835F8B39716A48FE1] [APT] [One-Click Optimizer WO12] (.Ashampoo Development GmbH & Co. KG.) -- C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\WO12.exe [8287088] [MD5.7F23D258460406B5B43E81BDF9AACD41] [APT] [SlimDrivers Startup] (.SlimWare Utilities, Inc..) -- C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [29731096] O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\Tasks\Adobe Flash Player Updater.job [1002] © O39 - APT: BeneFit - (...) -- C:\WINDOWS\Tasks\BeneFit.job [398] O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job [1196] © O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job [1200] © O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job [1078] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job [1082] © O39 - APT: SlimDrivers Startup - (.SlimWare Utilities, Inc..) -- C:\WINDOWS\Tasks\SlimDrivers Startup.job [426] O39 - APT: Adobe Acrobat Update Task - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task [3972] © O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater [3988] © O39 - APT: AutoPico Daily Restart - (.@ByELDI.) -- C:\WINDOWS\System32\Tasks\AutoPico Daily Restart [3460] =>HackTool.KMSpico O39 - APT: BeneFit - (...) -- C:\WINDOWS\System32\Tasks\BeneFit [3398] O39 - APT: CCleanerSkipUAC - (.Piriform Ltd.) -- C:\WINDOWS\System32\Tasks\CCleanerSkipUAC [2854] © O39 - APT: DropboxUpdateTaskMachineCore - (.Dropbox, Inc..) -- C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore [4028] © O39 - APT: DropboxUpdateTaskMachineUA - (.Dropbox, Inc..) -- C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA [4260] © O39 - APT: eM Client Database Backup - (...) -- C:\WINDOWS\System32\Tasks\eM Client Database Backup [4082] O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore [3908] © O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA [4140] © O39 - APT: One-Click Optimizer WO12 - (.Ashampoo Development GmbH & Co. KG.) -- C:\WINDOWS\System32\Tasks\One-Click Optimizer WO12 [3824] O39 - APT: SlimDrivers Startup - (.SlimWare Utilities, Inc..) -- C:\WINDOWS\System32\Tasks\SlimDrivers Startup [2910] ---\\ Processus lancés (46) - 0s [MD5.AC4F72ABB5ED596A0F3D9D1EDDC4B27C] - (.Intel Corporation - igfxCUIService Module.) -- C:\Windows\System32\igfxCUIService.exe [351120] [PID.1528] © [MD5.5DB2C6B908C50767E2EDAA294A7566B5] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128] [PID.2556] © [MD5.191E745BF2A451C716220FFD9AE25E15] - (...) -- C:\Program Files (x86)\Common Files\Microsoft\Care Suite\ADUService\ADUService.exe [94888] [PID.2564] [MD5.DAE6C3099D291EED8922A65C29ABCF52] - (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520] [PID.2572] © [MD5.DFEB7EE15BA8BA03E722C375F7E6A379] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE [136576] [PID.2580] © [MD5.4E1D29BD13F186158A4D788DF98984D1] - (.Intel® Corporation - CAMService Module.) -- C:\Program Files\Intel\CAM\bin\CAMService.exe [1243344] [PID.2588] © [MD5.FEC3A8349DCBECB87850692F1020B023] - (.Intel Corporation - Intel(R) Wireless Bluetooth(R) Radio Manage.) -- C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [155448] [PID.2596] © [MD5.AB176B9E59C0435499D83047D84EDD59] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784] [PID.2716] © [MD5.56F8A98F4F2AB9317B8E1E8E907CFD3C] - (.Nitro PDF Software - Nitro PDF Spool Service.) -- C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [324760] [PID.2776] © [MD5.AB38ABED6BA5A0BB2269525D87F284A9] - (.@ByELDI - Service_KMS.) -- C:\Program Files\KMSpico\Service_KMS.exe [971968] [PID.2816] =>HackTool.KMSpico [MD5.40C126CB15FAB7D6C66490DCA9C1AED2] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416] [PID.2836] © [MD5.6F2AD902A2BFD3D99C949FE12B66DD2C] - (...) -- C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [418968] [PID.2844] [MD5.CBE5708FAAD52FB7AD81F9545E9A4362] - (.VMware, Inc. - VMware Authorization Service.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe [87744] [PID.3020] © [MD5.2AA61246A5B813C1B12BCCFAA6F23DD8] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416] [PID.3028] © [MD5.160745D15B77381BA85F4C0191A7A249] - (.VMware, Inc. - VMware VMnet DHCP service.) -- C:\Windows\SysWOW64\vmnetdhcp.exe [359104] [PID.3036] © [MD5.5C98BFEE7BB8A4C06E3A9F5A93BC3D2F] - (.VMware, Inc. - VMware USB Arbitration Service.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [915648] [PID.3044] © [MD5.3F4EF498707EC875BD12E29DB1650D70] - (.VMware, Inc. - VMware NAT Service.) -- C:\Windows\SysWOW64\vmnat.exe [438464] [PID.3052] © [MD5.635686E528F2C9CB916EC1BB04EE6AD1] - (...) -- C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248736] [PID.3064] [MD5.BABBBDEF9DBB5E012EE5210FCB47C33B] - (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe [9832760] [PID.5260] © [MD5.6454CCB70AAA1487F779F31E37C14B13] - (.Intel Corporation - igfxEM Module.) -- C:\Windows\System32\igfxEM.exe [328080] [PID.6056] © [MD5.0B1B96CB8A81514B552F214436C89D88] - (.Intel Corporation - igfxHK Module.) -- C:\Windows\System32\igfxHK.exe [249232] [PID.6076] © [MD5.BA5E62B4485B83737579749DCE43EE85] - (...) -- C:\Windows\System32\igfxTray.exe [396688] [PID.6100] [MD5.A889E7974A7B9A41AF88B77E17627D26] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\TeamViewer.exe [18484496] [PID.6812] © [MD5.FBC76FB8AC96C179E4D0BC806B850748] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_w32.exe [230672] [PID.7956] © [MD5.24B9BA271BC87C8B9FC05A688923652F] - (.TeamViewer GmbH - TeamViewer 10.) -- C:\Program Files (x86)\TeamViewer\tv_x64.exe [263952] [PID.8020] © [MD5.7F23D258460406B5B43E81BDF9AACD41] - (.SlimWare Utilities, Inc. - SlimDrivers.) -- C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe [29731096] [PID.3500] [MD5.A72BB48D9014A7D7C05F02F595F52D60] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler.exe [245576] [PID.3800] © [MD5.E337785DA1958E9AB02DDB2369EF46E8] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.28.15\GoogleCrashHandler64.exe [307016] [PID.7564] © [MD5.6BCE148DE6670CFB44828B8497E089F6] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13774040] [PID.8528] © [MD5.585462051E79B30D0282D246F583977D] - (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE [241280] [PID.8560] © [MD5.B7D9DE6A47C9581803159756E86CC698] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [870728] [PID.8332] © [MD5.B7D9DE6A47C9581803159756E86CC698] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [870728] [PID.8736] © [MD5.7CEAEBABAA8F8BE09936E2D8C97891F7] - (.Dropbox, Inc. - Dropbox.) -- C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36713096] [PID.9016] © [MD5.B7D9DE6A47C9581803159756E86CC698] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [870728] [PID.9140] © [MD5.76EC49E2394B0D239743359C2EB73657] - (.Synology Inc. - .) -- C:\Users\Olivier\AppData\Local\CloudStation\CloudStation.app\bin\cloud-ui.exe [4447664] [PID.9100] © [MD5.1A7AC743BB096371DA8058FBC74D9935] - (.Synology Inc. - .) -- C:\Users\Olivier\AppData\Local\CloudStation\CloudStation.app\bin\cloud-connect.exe [3499512] [PID.484] © [MD5.F458F8485F4E1A4983DC3A835BFFCB71] - (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [113344] [PID.8904] © [MD5.40335C8877B6B84842AF03A40E1BB206] - (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe [8591272] [PID.8336] © [MD5.663422B0E2EFEFBC56DD5313196700E8] - (.Synology Inc. - .) -- C:\Users\Olivier\AppData\Local\CloudStation\CloudStation.app\bin\cloud-daemon.exe [20629488] [PID.8524] © [MD5.B7D9DE6A47C9581803159756E86CC698] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [870728] [PID.1144] © [MD5.3D45AD2B246B90DBD3E6F213E7AEBF64] - (.Intel Corporation - IAStorIcon.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592] [PID.6260] © [MD5.33BFEC2B102B196B62ABB9947C7D7E23] - (.Dropbox, Inc. - Dropbox Update.) -- C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048] [PID.9528] © [MD5.20E83F4632E15A5E9E716FF2E8AC7FAE] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720] [PID.2800] © [MD5.52069AEB42D3D0F97CBCA1085EBF55E6] - (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432] [PID.9236] © [MD5.E2952760B05A256FB1412D20A41C89C1] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [390616] [PID.10212] © [MD5.4E980078E8F1F28EEF6A00F1347D868E] - (.Copyright (C) 2015 Nicolas Coolman - ZHPDiag.) -- \\DISKSTATION\Downloads\ZHPDiag3.exe [1976320] [PID.10232] © ---\\ Google Chrome, Démarrage,Recherche,Extensions (9) - 0s G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] __MSG_extName__ G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. ---\\ Firefox, Plugins,Demarrage,Recherche,Extensions (17) - 1s P2 - EXT: (...) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.FRA P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\jid1-ach2kaGSshPJCg@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\jid1-sNL73VCI4UB0Fw@jetpack.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi P2 - EXT FILE: (...) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi =>Adware.Sambreel P2 - EXT: (.Mozilla - Default.) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} © P2 - EXT: (.Ant.com - Ant Video Downloader.) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\anttoolbar@ant.com © P2 - EXT: (. - Flash Video Downloader - YouTube HD Download [4K].) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\artur.dubovoy@gmail.com P2 - EXT: (.O-Minds (http://www.o-minds.com/) - FlashFirebug.) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\flashfirebug@o-minds.com P2 - EXT: (.Vicente Amor - Flash and Video Download.) -- C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} © P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll © P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp] - (...) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll P2 - FPN: [HKLM] [@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf] - (...) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll ---\\ Internet Explorer,Démarrage,Recherche,URLSearchHook (8) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mail.ru/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/ R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/ R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphean =>.Microsoft Internet Explorer R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV9 = 1 ---\\ Internet Explorer,Proxy Management (5) - 0s R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1 R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll ---\\ Internet Explorer,IniFiles, Autoloading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe (.Microsoft Corporation.) © F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe (.Microsoft Corporation.) © F2 - REG:system.ini: VMApplet= ---\\ Etude du fichier hosts (1) - 1s ~ Le fichier hôte est sain (The hosts file is clean) (15639) ---\\ Browser Helper Object de navigateur (BHO) (5) - 0s O2 - BHO: Skype for Business Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Skype for Business.) -- C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll © O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Orphean) O2 - BHO: Microsoft SkyDrive Pro Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} . (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL © O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} (Orphean) O2 - BHO: DownloadHelper Class [64Bits] - {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} . (.IE Download Helper - IE Download Helper Plugin.) -- C:\Program Files (x86)\Common Files\Download Helper\DownloadHelper.dll ---\\ Applications lancées au démarrage du système (31) - 0s O4 - HKLM\..\Run: [RTHDVCPL] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe © O4 - HKLM\..\Run: [MouseDriver] . (.Pixart Imaging Inc - pximouse.) -- C:\WINDOWS\System32\TiltWheelMouse.exe O4 - HKLM\..\Run: [IgfxTray] . (...) -- C:\Windows\System32\igfxTray.exe O4 - HKLM\..\Run: [IAStorIcon] . (.Intel Corporation - Delayed launcher.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe © O4 - HKLM\..\Run: [Windows Mobile Device Center] . (.Microsoft Corporation - Gestionnaire pour appareils Windows Mobile.) -- C:\Windows\WindowsMobile\wmdc.exe © O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE © O4 - HKCU\..\Run: [eM Client] . (.eM Client, Inc. - eM Client.) -- C:\Program Files (x86)\eM Client\MailClient.exe O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKCU\..\Run: [ryfrdatfqz] explorer http://slezaba.ru/?utm_source=uoua03&utm_content=24e5270a08646ced32d8e898a63e55ae&utm_term=72A0E9D377BD6BADD43B031565549CE8 O4 - HKCU\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKLM\..\Wow6432Node\Run: [PWRISOVM.EXE] . (.Power Software Ltd - PowerISO Virtual Drive Manager.) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE © O4 - HKLM\..\Wow6432Node\Run: [DivXMediaServer] . (.DivX, LLC - DivX Media Server Launcher.) -- C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe © O4 - HKLM\..\Wow6432Node\Run: [DivXUpdate] . (.DivX, LLC - DivX Binary File.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe © O4 - HKLM\..\Wow6432Node\Run: [Dropbox] . (.Dropbox, Inc. - Dropbox.) -- C:\Program Files (x86)\Dropbox\Client\Dropbox.exe © O4 - HKLM\..\Wow6432Node\Run: [vmware-tray.exe] . (.VMware, Inc. - VMware Tray Process.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe © O4 - HKLM\..\Wow6432Node\Run: [Wondershare Helper Compact.exe] . (.Wondershare - Wondershare Studio.) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe © O4 - HKUS\.DEFAULT\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE © O4 - HKUS\S-1-5-18\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE © O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\Run: [EPLTarget\P0000000000000000] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\System32\spool\drivers\x64\3\E_YATIHTE.EXE © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\Run: [eM Client] . (.eM Client, Inc. - eM Client.) -- C:\Program Files (x86)\eM Client\MailClient.exe O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\OneDrive.exe © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\Run: [ryfrdatfqz] explorer http://slezaba.ru/?utm_source=uoua03&utm_content=24e5270a08646ced32d8e898a63e55ae&utm_term=72A0E9D377BD6BADD43B031565549CE8 O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\Run: [CCleaner Monitoring] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © O4 - HKUS\S-1-5-21-2682806266-4194798205-1814897153-1001\..\RunOnce: [Uninstall C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.5951.0827\amd64] . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\System32\cmd.exe © ---\\ Modification Domaine/Adresses DNS (8) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 178.32.122.65,37.187.0.40 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.240 192.168.1.241 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpDomain = hdg.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 178.32.122.65,37.187.0.40 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.240 192.168.1.241 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: DhcpDomain = hdg.local ---\\ Protocole additionnel (23) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll © O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll © O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll © O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\SysWOW64\urlmon.dll © O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll © O18 - Handler: osf [64Bits] - {D924BDC6-C83A-4BD5-90D0-095128A113D1} . (.Microsoft Corporation - Microsoft Office 2013 component.) -- C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL © O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll © O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\SysWOW64\MSVidCtl.dll © O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\SysWOW64\mshtml.dll © O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll © O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL © ---\\ Contenu des dossiers Programmes (335) - 5s O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\AC3Filter O43 - CFD: 07/07/2015 - [] D -- C:\Program Files (x86)\Adobe O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Ant Renamer O43 - CFD: 11/08/2015 - [] D -- C:\Program Files (x86)\Ashampoo O43 - CFD: 06/05/2015 - [] D -- C:\Program Files (x86)\Audacity O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\AviSynth O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\BadgerIT O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Biomobility, LLC O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Ciel O43 - CFD: 05/04/2015 - [0] D -- C:\Program Files (x86)\Cisco O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\Common Files O43 - CFD: 14/07/2015 - [] D -- C:\Program Files (x86)\CutTHEPrrice =>PUP.Optional.Multiplug O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Data On The Run 5 O43 - CFD: 16/06/2015 - [] D -- C:\Program Files (x86)\Data On The Run Installer O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\DirectVobSub O43 - CFD: 11/11/2015 - [] D -- C:\Program Files (x86)\DivX O43 - CFD: 10/11/2015 - [] D -- C:\Program Files (x86)\Dropbox O43 - CFD: 12/07/2015 - [] D -- C:\Program Files (x86)\Druide O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\DVD Flick O43 - CFD: 11/07/2015 - [] D -- C:\Program Files (x86)\DVD Shrink O43 - CFD: 09/10/2015 - [] D -- C:\Program Files (x86)\eM Client O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\epson O43 - CFD: 25/10/2015 - [] D -- C:\Program Files (x86)\FairUse Wizard 3D O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Fintek Inc O43 - CFD: 08/04/2015 - [] D -- C:\Program Files (x86)\Flash Video Downloader O43 - CFD: 12/04/2015 - [] D -- C:\Program Files (x86)\foobar2000 O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\FreeTime O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Google O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Hewlett-Packard O43 - CFD: 23/11/2015 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Intel O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Intel Driver Update Utility O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\Internet Explorer O43 - CFD: 10/06/2015 - [] D -- C:\Program Files (x86)\iPAQ 210 Series Power Button Resume Failed Fix O43 - CFD: 11/06/2015 - [] D -- C:\Program Files (x86)\IVT Corporation O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\JAM Software O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\K-Lite Codec Pack O43 - CFD: 07/05/2015 - [] D -- C:\Program Files (x86)\Lame For Audacity O43 - CFD: 07/06/2015 - [] D -- C:\Program Files (x86)\LAV Filters O43 - CFD: 07/06/2015 - [] D -- C:\Program Files (x86)\Ligos O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\m4ng codec pack O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\m4ng_v5 O43 - CFD: 23/11/2015 - [0] D -- C:\Program Files (x86)\Mail.Ru O43 - CFD: 13/10/2015 - [] D -- C:\Program Files (x86)\Malwarebytes Anti-Malware O43 - CFD: 19/04/2015 - [] D -- C:\Program Files (x86)\Medieval Software O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Microsoft Analysis Services O43 - CFD: 11/11/2015 - [] D -- C:\Program Files (x86)\Microsoft Care Suite O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Microsoft LifeCam O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Microsoft Office O43 - CFD: 13/08/2015 - [] D -- C:\Program Files (x86)\Microsoft Silverlight O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Microsoft SQL Server O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\Microsoft Sync Framework O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Microsoft.NET O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\MKVtoolnix O43 - CFD: 09/05/2015 - [] D -- C:\Program Files (x86)\Monkey's Audio O43 - CFD: 19/09/2015 - [] D -- C:\Program Files (x86)\Mozilla Firefox O43 - CFD: 19/09/2015 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service O43 - CFD: 02/11/2015 - [] D -- C:\Program Files (x86)\Mp3tag O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\MSBuild O43 - CFD: 22/11/2015 - [0] D -- C:\Program Files (x86)\MyFree Codec O43 - CFD: 12/07/2015 - [] D -- C:\Program Files (x86)\Nitro O43 - CFD: 11/11/2015 - [] D -- C:\Program Files (x86)\Nokia O43 - CFD: 12/07/2015 - [] D -- C:\Program Files (x86)\Nuvoton Technology Corp O43 - CFD: 11/07/2015 - [] D -- C:\Program Files (x86)\OVH O43 - CFD: 12/04/2015 - [] D -- C:\Program Files (x86)\PhotoFiltre 7 O43 - CFD: 01/06/2015 - [] D -- C:\Program Files (x86)\PowerISO O43 - CFD: 12/07/2015 - [0] D -- C:\Program Files (x86)\ReactorKeeper O43 - CFD: 06/04/2015 - [] D -- C:\Program Files (x86)\Realtek O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Reference Assemblies O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\Remove Empty Directories O43 - CFD: 23/11/2015 - [] D -- C:\Program Files (x86)\Samsung O43 - CFD: 06/04/2015 - [] D -- C:\Program Files (x86)\SlimDrivers O43 - CFD: 14/09/2015 - [] D -- C:\Program Files (x86)\SyncToy 2.1 O43 - CFD: 12/05/2015 - [] D -- C:\Program Files (x86)\Synology O43 - CFD: 27/11/2015 - [] D -- C:\Program Files (x86)\TeamViewer O43 - CFD: 06/04/2015 - [0] HD -- C:\Program Files (x86)\Temp O43 - CFD: 04/10/2015 - [] D -- C:\Program Files (x86)\TubeDigger O43 - CFD: 19/09/2015 - [] D -- C:\Program Files (x86)\UnderCover10 O43 - CFD: 27/09/2015 - [] D -- C:\Program Files (x86)\VirtualDub O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\VirtualDub-Fr O43 - CFD: 16/11/2015 - [] D -- C:\Program Files (x86)\VMware O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Defender O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Windows Mail O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Media Player O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows NT O43 - CFD: 07/04/2015 - [] D -- C:\Program Files (x86)\Windows Phone O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Photo Viewer O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Windows Portable Devices O43 - CFD: 10/07/2015 - [] SHD -- C:\Program Files (x86)\Windows Sidebar O43 - CFD: 10/07/2015 - [] SD -- C:\Program Files (x86)\WindowsPowerShell O43 - CFD: 24/05/2015 - [] D -- C:\Program Files (x86)\WYSIWYG Web Builder 10 O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\Xilisoft O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\XnView O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\Xvid O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter O43 - CFD: 06/10/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 24/09/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ant Renamer O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth O43 - CFD: 23/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BadgerIT O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ciel O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpoweramp O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX O43 - CFD: 10/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Video Downloader O43 - CFD: 23/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome O43 - CFD: 28/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Driver Update Utility O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack O43 - CFD: 22/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LAV Filters O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 13/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medieval Software O43 - CFD: 11/11/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVtoolnix O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MoM O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Monkey's Audio O43 - CFD: 02/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag O43 - CFD: 27/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QGIS Wien O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remove Empty Directories O43 - CFD: 23/11/2015 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ReviverSoft O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers O43 - CFD: 28/08/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Synology O43 - CFD: 10/07/2015 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 10/07/2015 - [0] RHD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free O43 - CFD: 04/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TubeDigger O43 - CFD: 19/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnderCover10 O43 - CFD: 27/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtualDub O43 - CFD: 16/11/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WYSIWYG Web Builder 10 O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft O43 - CFD: 14/09/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XnView O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid O43 - CFD: 07/07/2015 - [] D -- C:\ProgramData\Adobe O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Application Data O43 - CFD: 07/04/2015 - [] D -- C:\ProgramData\Applications O43 - CFD: 11/08/2015 - [] D -- C:\ProgramData\Ashampoo O43 - CFD: 09/04/2015 - [] D -- C:\ProgramData\Avanquest Software O43 - CFD: 10/05/2015 - [] D -- C:\ProgramData\Baidu O43 - CFD: 05/04/2015 - [0] SHD -- C:\ProgramData\Bureau O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Ciel O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\ClassicShell O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\Comms O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Desktop O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\DivX O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Documents O43 - CFD: 16/06/2015 - [] D -- C:\ProgramData\Dropbox O43 - CFD: 05/10/2015 - [] D -- C:\ProgramData\DVD Shrink O43 - CFD: 08/04/2015 - [] D -- C:\ProgramData\EPSON O43 - CFD: 09/11/2015 - [] D -- C:\ProgramData\HTC O43 - CFD: 12/06/2015 - [] D -- C:\ProgramData\IDMComp O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Intel O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\IntelDLM O43 - CFD: 09/11/2015 - [] D -- C:\ProgramData\LGE O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Mail.Ru O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Malwarebytes O43 - CFD: 05/04/2015 - [0] SHD -- C:\ProgramData\Menu Démarrer O43 - CFD: 09/11/2015 - [] SD -- C:\ProgramData\Microsoft O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\Microsoft Help O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\Microsoft OneDrive O43 - CFD: 23/09/2015 - [] D -- C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS O43 - CFD: 05/04/2015 - [0] SHD -- C:\ProgramData\Modèles O43 - CFD: 04/10/2015 - [] D -- C:\ProgramData\Movavi O43 - CFD: 04/10/2015 - [] D -- C:\ProgramData\Movavi Video Converter 16 O43 - CFD: 08/04/2015 - [] D -- C:\ProgramData\Mozilla O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Nitro O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\Nokia O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Oracle O43 - CFD: 11/11/2015 - [] D -- C:\ProgramData\Package Cache O43 - CFD: 06/04/2015 - [] D -- C:\ProgramData\PC1Data O43 - CFD: 27/10/2015 - [] D -- C:\ProgramData\PDF Architect 4 O43 - CFD: 28/08/2015 - [] D -- C:\ProgramData\regid.1991-06.com.microsoft O43 - CFD: 08/11/2015 - [] D -- C:\ProgramData\ReviverSoft O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Roaming O43 - CFD: 22/11/2015 - [] D -- C:\ProgramData\Samsung O43 - CFD: 10/05/2015 - [] D -- C:\ProgramData\Skype O43 - CFD: 06/04/2015 - [] D -- C:\ProgramData\SlimWare Utilities, Inc O43 - CFD: 10/07/2015 - [0] D -- C:\ProgramData\SoftwareDistribution O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Start Menu O43 - CFD: 05/04/2015 - [] D -- C:\ProgramData\Sun O43 - CFD: 05/04/2015 - [0] D -- C:\ProgramData\Synology O43 - CFD: 10/07/2015 - [0] SHD -- C:\ProgramData\Templates O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOPrivate O43 - CFD: 10/07/2015 - [] D -- C:\ProgramData\USOShared O43 - CFD: 27/11/2015 - [] D -- C:\ProgramData\VMware O43 - CFD: 07/07/2015 - [] D -- C:\Program Files (x86)\Common Files\Adobe O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Ciel O43 - CFD: 05/10/2015 - [] D -- C:\Program Files (x86)\Common Files\DivX Shared O43 - CFD: 08/04/2015 - [] D -- C:\Program Files (x86)\Common Files\Download Helper O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Common Files\InstallShield O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Common Files\Intel Corporation O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Common Files\Java O43 - CFD: 11/11/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Microsoft Shared O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Common Files\MSSoap O43 - CFD: 11/11/2015 - [] D -- C:\Program Files (x86)\Common Files\Nokia O43 - CFD: 05/04/2015 - [] D -- C:\Program Files (x86)\Common Files\postureAgent O43 - CFD: 28/08/2015 - [] D -- C:\Program Files (x86)\Common Files\Sage O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\Services O43 - CFD: 10/07/2015 - [] D -- C:\Program Files (x86)\Common Files\System O43 - CFD: 16/11/2015 - [] D -- C:\Program Files (x86)\Common Files\VMware O43 - CFD: 21/11/2015 - [] D -- C:\Program Files (x86)\Common Files\Wondershare O43 - CFD: 20/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\AccurateRip O43 - CFD: 08/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Adobe O43 - CFD: 09/05/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Audacity O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\ClassicShell O43 - CFD: 20/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\dBpoweramp O43 - CFD: 25/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\DivX O43 - CFD: 12/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Downloaded Installations O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Dropbox O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Druide O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\dvdcss O43 - CFD: 11/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\eM Client O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\EPSON O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\foobar2000 O43 - CFD: 09/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Foxit Software O43 - CFD: 12/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\gSyncit O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\HandBrake O43 - CFD: 06/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Identities O43 - CFD: 12/06/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\IDMComp O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Intel O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Intel Corporation O43 - CFD: 14/09/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\JAM Software O43 - CFD: 15/08/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Likno Software O43 - CFD: 06/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\m4ng O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Macromedia O43 - CFD: 14/09/2015 - [] SD -- C:\Users\Olivier\AppData\Roaming\Microsoft O43 - CFD: 08/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Mozilla O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Mp3tag O43 - CFD: 27/11/2015 - [0] D -- C:\Users\Olivier\AppData\Roaming\MPC-HC O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Nitro O43 - CFD: 12/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Nitro PDF O43 - CFD: 27/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\PDF Architect 4 O43 - CFD: 09/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\PDF Pro 10 O43 - CFD: 12/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\PhotoFiltre 7 O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Quittance Express 3 O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Samsung O43 - CFD: 08/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Shortcut O43 - CFD: 10/05/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Skype O43 - CFD: 30/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\TeamViewer O43 - CFD: 23/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\uTorrent O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\VMware O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\WinRAR O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Xilisoft O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\XnView O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\ZHP O43 - CFD: 08/07/2015 - [] D -- C:\Users\Olivier\AppData\Local\Adobe O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Aiseesoft Studio O43 - CFD: 28/08/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\Application Data O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\ApplicationHistory O43 - CFD: 26/07/2015 - [] D -- C:\Users\Olivier\AppData\Local\Apps O43 - CFD: 27/11/2015 - [] RD -- C:\Users\Olivier\AppData\Local\Biomobility O43 - CFD: 09/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\CEF O43 - CFD: 29/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\ClassicShell O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\CloudStation O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\Comms O43 - CFD: 04/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\converter O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Diagnostics O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Downloaded Installations O43 - CFD: 12/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\Dropbox O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\ElevatedDiagnostics O43 - CFD: 10/06/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\EmieBrowserModeList O43 - CFD: 10/06/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\EmieSiteList O43 - CFD: 10/06/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\EmieUserList O43 - CFD: 09/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\Foxit Reader O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Google O43 - CFD: 02/06/2015 - [] D -- C:\Users\Olivier\AppData\Local\GWX O43 - CFD: 28/08/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\Historique O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\Intel O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\labDV.com O43 - CFD: 12/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\Macromedia O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Mail.Ru O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\MailRu O43 - CFD: 11/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Microsoft O43 - CFD: 02/05/2015 - [] D -- C:\Users\Olivier\AppData\Local\Microsoft Help O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\MicrosoftEdge O43 - CFD: 04/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\Movavi O43 - CFD: 08/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\Mozilla O43 - CFD: 22/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\MSfree Inc O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Packages O43 - CFD: 05/04/2015 - [0] D -- C:\Users\Olivier\AppData\Local\PackageStaging O43 - CFD: 27/10/2015 - [0] D -- C:\Users\Olivier\AppData\Local\PDFCreator O43 - CFD: 28/08/2015 - [0] D -- C:\Users\Olivier\AppData\Local\PeerDistRepub O43 - CFD: 05/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\Programs O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\Publishers O43 - CFD: 12/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\Remove_Empty_Directories O43 - CFD: 22/11/2015 - [0] D -- C:\Users\Olivier\AppData\Local\Samsung O43 - CFD: 10/05/2015 - [] D -- C:\Users\Olivier\AppData\Local\Skype O43 - CFD: 06/04/2015 - [] D -- C:\Users\Olivier\AppData\Local\SlimWare Utilities Inc O43 - CFD: 08/04/2015 - [0] D -- C:\Users\Olivier\AppData\Local\StormFall =>PUP.Optional.StormFall O43 - CFD: 08/07/2015 - [] D -- C:\Users\Olivier\AppData\Local\TeamViewer O43 - CFD: 27/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Temp O43 - CFD: 28/08/2015 - [0] SHD -- C:\Users\Olivier\AppData\Local\Temporary Internet Files O43 - CFD: 28/08/2015 - [] D -- C:\Users\Olivier\AppData\Local\TileDataLayer O43 - CFD: 07/06/2015 - [] D -- C:\Users\Olivier\AppData\Local\VirtualStore O43 - CFD: 23/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\VMware O43 - CFD: 21/11/2015 - [] D -- C:\Users\Olivier\AppData\Local\Wondershare O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Local\_VideoConverter O43 - CFD: 10/07/2015 - [] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility O43 - CFD: 27/11/2015 - [] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories O43 - CFD: 27/10/2015 - [] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth O43 - CFD: 16/06/2015 - [0] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVDx 4.1 O43 - CFD: 17/09/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FairUse Wizard 3D O43 - CFD: 22/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory O43 - CFD: 07/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\m4ng Codec Pack O43 - CFD: 05/10/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\m4ng_v5 O43 - CFD: 10/07/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance O43 - CFD: 01/11/2015 - [] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo O43 - CFD: 12/04/2015 - [0] D -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7 O43 - CFD: 27/10/2015 - [] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup O43 - CFD: 10/07/2015 - [] RD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools O43 - CFD: 10/07/2015 - [] RSD -- C:\Users\Olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell ---\\ Derniers fichiers créés dans Windows Prefetcher (1) - 4s O45 - LFCP:[MD5.312FE1502481CC31E1DB0621EE97DEBE] 08/11/2015 A -- C:\WINDOWS\Prefetch\DRIVERREVIVER.EXE-0E603A48.pf =>PUP.Optional.DriverReviver ---\\ ShellIconOverlayIdentifiers (SIOI) (16) - 0s O106 - SIOI: DropboxExt1 Class [ DropboxExt1] - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt2 Class [ DropboxExt2] - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt5 Class [ DropboxExt3] - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt6 Class [ DropboxExt4] - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt3 Class [ DropboxExt5] - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt7 Class [ DropboxExt6] - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt4 Class [ DropboxExt7] - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: DropboxExt8 Class [ DropboxExt8] - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B}. (.Dropbox, Inc. - Dropbox Shell Extension.) -- C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll © O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll © O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll © O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll © O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll © O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\Olivier\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileSyncShell.dll © O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) [ SkyDrivePro1 (ErrorConflict)] - {8BA85C75-763B-4103-94EB-9470F12FE0F7}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL © O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) [ SkyDrivePro2 (SyncInProgress)] - {CD55129A-B1A1-438E-A425-CEBC7DC684EE}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL © O106 - SIOI: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) [ SkyDrivePro3 (InSync)] - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1}. (.Microsoft Corporation - Microsoft OneDrive for Business Extensions.) -- C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL © ---\\ Liste des pilotes du système (74) - 2s O58 - SDL:2015/09/12 17:38:45 A . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\03FB6422.sys [113880] © O58 - SDL:2015/07/10 11:59:38 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\WINDOWS\System32\drivers\3ware.sys [107360] © O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\WINDOWS\System32\drivers\adp80xx.sys [1135456] © O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\WINDOWS\System32\drivers\amdsata.sys [83296] © O58 - SDL:2015/07/10 11:59:38 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\WINDOWS\System32\drivers\amdsbs.sys [259424] © O58 - SDL:2015/07/10 11:59:38 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\WINDOWS\System32\drivers\amdxata.sys [26976] © O58 - SDL:2015/07/10 11:59:38 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\WINDOWS\System32\drivers\arcsas.sys [131936] © O58 - SDL:2015/07/10 11:59:38 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\WINDOWS\System32\drivers\bcmfn2.sys [17624] © O58 - SDL:2013/10/08 17:23:28 A . (.IVT Corporation. - Bluetooth HID BUS Driver.) -- C:\WINDOWS\System32\drivers\BtHidBus.sys [24032] O58 - SDL:2012/12/24 15:42:26 A . (.IVT Corporation. - Bluetooth PAN Network Bus Driver.) -- C:\WINDOWS\System32\drivers\btnetBus.sys [31480] O58 - SDL:2012/08/03 10:42:24 A . (.Windows (R) Win 7 DDK provider - Synology Virtual USB Hub.) -- C:\WINDOWS\System32\drivers\busenum.sys [57824] © O58 - SDL:2015/07/10 11:59:38 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\WINDOWS\System32\drivers\bxvbda.sys [531296] © O58 - SDL:2015/07/10 11:59:38 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\WINDOWS\System32\drivers\evbda.sys [3436896] © O58 - SDL:2015/10/21 12:41:28 A . (.VMware, Inc. - VMware USB monitor.) -- C:\WINDOWS\System32\drivers\hcmon.sys [55488] © O58 - SDL:2015/07/10 11:59:38 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\WINDOWS\System32\drivers\HpSAMD.sys [64352] © O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys [38128] © O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys [122608] © O58 - SDL:2013/08/07 13:23:46 A . (.Intel Corporation - Intel Rapid Storage Technology driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorA.sys [644968] © O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\WINDOWS\System32\drivers\iaStorAV.sys [673120] © O58 - SDL:2015/07/10 11:59:38 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\WINDOWS\System32\drivers\iaStorV.sys [412000] © O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\WINDOWS\System32\drivers\ibbus.sys [424800] © O58 - SDL:2015/07/14 19:27:40 A . (.Intel Corporation - Intel(R) Wireless Bluetooth(R) USB Driver.) -- C:\WINDOWS\System32\drivers\ibtusb.sys [263952] © O58 - SDL:2015/07/17 23:36:32 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\WINDOWS\System32\drivers\igdkmd64.sys [6389688] © O58 - SDL:2015/03/06 15:59:34 N . (.Intel(R) Corporation - Intel(R) Display Audio Driver.) -- C:\WINDOWS\System32\drivers\IntcDAud.sys [455440] © O58 - SDL:2012/12/24 15:45:48 A . (.IVT Corporation. - IVT Bluetooth Bus Device Driver.) -- C:\WINDOWS\System32\drivers\IvtBtBus.sys [27256] O58 - SDL:2015/05/26 17:20:28 A . (.Intel Corporation - Intel® WiDi Solution.) -- C:\WINDOWS\System32\drivers\iwdbus.sys [30512] © O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas.sys [108896] © O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas2i.sys [104800] © O58 - SDL:2015/07/10 11:59:38 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sas3i.sys [99168] © O58 - SDL:2015/07/10 11:59:38 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\WINDOWS\System32\drivers\lsi_sss.sys [82784] © O58 - SDL:2015/10/05 08:50:06 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [25816] © O58 - SDL:2015/10/05 08:50:10 A . (.Malwarebytes - Malwarebytes Chameleon Protection Driver.) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys [109272] © O58 - SDL:2015/11/27 23:04:35 A . (.Malwarebytes - Malwarebytes Anti-Malware.) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [192216] © O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\megasas.sys [59744] © O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\WINDOWS\System32\drivers\megasr.sys [575840] © O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - MLX4 Bus Driver.) -- C:\WINDOWS\System32\drivers\mlx4_bus.sys [705376] © O58 - SDL:2015/07/10 11:59:39 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\WINDOWS\System32\drivers\mvumis.sys [63840] © O58 - SDL:2015/10/05 08:50:22 A . (.Malwarebytes Corporation - Malwarebytes Web Access Control.) -- C:\WINDOWS\System32\drivers\mwac.sys [64216] © O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\WINDOWS\System32\drivers\ndfltr.sys [76128] © O58 - SDL:2015/07/10 11:59:36 A . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\WINDOWS\System32\drivers\Netwbw02.sys [3496216] © O58 - SDL:2013/07/11 17:07:34 A . (.Nuvoton Technology Corp. - Nuvoton SIO CIR Device Driver.) -- C:\WINDOWS\System32\drivers\nuviocir_x64.sys [39704] O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\WINDOWS\System32\drivers\nvraid.sys [150368] © O58 - SDL:2015/07/10 11:59:39 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\WINDOWS\System32\drivers\nvstor.sys [166240] © O58 - SDL:2015/07/10 11:59:39 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas2i.sys [58208] © O58 - SDL:2015/07/10 11:59:39 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\WINDOWS\System32\drivers\percsas3i.sys [58720] © O58 - SDL:2015/07/10 11:59:39 A . (.Realtek - Realtek 8136/8168/8169 NDIS 6.40 64-bit Dri.) -- C:\WINDOWS\System32\drivers\rt640x64.sys [587264] © O58 - SDL:2000/01/01 01:00:00 A . (.Realtek Semiconductor Corp. - Realtek(r) High Definition Audio Function D.) -- C:\WINDOWS\System32\drivers\RTKVHD64.sys [4263128] © O58 - SDL:2014/11/06 09:54:07 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsBaStor.sys [313048] © O58 - SDL:2014/11/06 10:07:08 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsP2Stor.sys [294104] © O58 - SDL:2014/12/23 02:52:22 A . (.Realsil Semiconductor Corporation - RTS PCIE READER Driver.) -- C:\WINDOWS\System32\drivers\RtsPer.sys [788696] © O58 - SDL:2014/11/06 09:57:44 A . (.Realtek Semiconductor Corp. - Realtek Pcie CardReader Driver for 2K/XP/Vi.) -- C:\WINDOWS\System32\drivers\RtsPStor.sys [359128] © O58 - SDL:2015/05/14 11:10:30 A . (.Realsil Semiconductor Corporation - RTS USB READER Driver.) -- C:\WINDOWS\System32\drivers\RtsUer.sys [402960] © O58 - SDL:2013/08/10 09:27:54 RA . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP/V.) -- C:\WINDOWS\System32\drivers\RtsUVStor.sys [329944] © O58 - SDL:2015/04/08 06:01:26 A . (.Power Software Ltd - PowerISO Virtual Drive.) -- C:\WINDOWS\System32\drivers\scdemu.sys [127760] © O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid2.sys [44896] © O58 - SDL:2015/07/10 11:59:39 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\WINDOWS\System32\drivers\sisraid4.sys [81760] © O58 - SDL:2015/07/10 11:59:39 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\WINDOWS\System32\drivers\stexstor.sys [31072] © O58 - SDL:2015/11/27 23:04:40 A . (.SlimWare Utilities, Inc. - Driver Update Installer Monitor.) -- C:\WINDOWS\System32\drivers\SWDUMon.sys [16056] O58 - SDL:2013/08/22 13:40:24 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver.) -- C:\WINDOWS\System32\drivers\tap0901.sys [40664] © O58 - SDL:2000/01/01 01:00:00 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\WINDOWS\System32\drivers\TeeDriverx64.sys [100312] © O58 - SDL:2013/04/09 09:42:06 A . (...) -- C:\WINDOWS\System32\drivers\t_mouse.sys [6144] O58 - SDL:2015/07/10 11:59:48 A . (...) -- C:\WINDOWS\System32\drivers\Udecx.sys [44032] O58 - SDL:2012/10/17 08:46:46 A . (.Fintek - USB Charger.) -- C:\WINDOWS\System32\drivers\USBCharger.sys [17768] O58 - SDL:2015/05/21 17:35:56 A . (.VMware, Inc. - VMware PCI VMCI Bus Device.) -- C:\WINDOWS\System32\drivers\vmci.sys [85584] © O58 - SDL:2015/11/03 19:49:44 A . (.VMware, Inc. - VMware virtual network driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnet.sys [27328] © O58 - SDL:2015/11/03 19:49:44 A . (.VMware, Inc. - VMware virtual network adapter driver (64-b.) -- C:\WINDOWS\System32\drivers\vmnetadapter.sys [28864] © O58 - SDL:2015/11/03 19:49:44 A . (.VMware, Inc. - VMware bridge driver (64-bit).) -- C:\WINDOWS\System32\drivers\vmnetbridge.sys [48832] © O58 - SDL:2015/11/03 19:49:58 A . (.VMware, Inc. - VMware network application interface driver.) -- C:\WINDOWS\System32\drivers\vmnetuserif.sys [26816] © O58 - SDL:2015/11/03 19:50:06 A . (.VMware, Inc. - VMware kernel driver.) -- C:\WINDOWS\System32\drivers\vmx86.sys [66752] © O58 - SDL:2015/07/10 11:59:39 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\WINDOWS\System32\drivers\vsmraid.sys [166752] © O58 - SDL:2015/05/21 17:36:00 A . (.VMware, Inc. - VMware vSockets Service.) -- C:\WINDOWS\System32\drivers\vsock.sys [76480] © O58 - SDL:2015/07/10 11:59:39 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\WINDOWS\System32\drivers\VSTXRAID.SYS [305504] © O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinMad.) -- C:\WINDOWS\System32\drivers\winmad.sys [26976] © O58 - SDL:2015/07/10 11:59:39 A . (.Mellanox - Kernel WinVerbs.) -- C:\WINDOWS\System32\drivers\winverbs.sys [59232] © ---\\ Derniers fichiers modifiés ou crées (Utilisateur) (8) - 7s O61 - LFC: 2015/11/27 23:04:40 A . (.SlimWare Utilities, Inc..) -- C:\Users\Olivier\AppData\Local\SlimWare Utilities Inc\SlimDrivers\SWDUMon.sys [16056] O61 - LFC: 2015/11/22 11:42:17 A . (..) -- C:\Users\Olivier\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Data.bin [4223068] O61 - LFC: 2015/11/22 11:42:18 A . (..) -- C:\Users\Olivier\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_0_Header.bin [32104] O61 - LFC: 2015/11/27 23:04:02 A . (..) -- C:\Users\Olivier\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\LocalState\speech_onecorereg.bin [8192] O61 - LFC: 2015/11/27 22:42:28 A . (..) -- C:\Users\Olivier\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\UrlBlock\urlblock_635842507098578141.bin [56936] O61 - LFC: 2015/11/27 19:29:27 A . (.Copyright (C) 2000.) -- C:\Users\Olivier\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cache\H3ZGPJ3Y\noscript[1].exe [127432] O61 - LFC: 2015/11/23 18:27:44 A . (..) -- C:\Users\Olivier\AppData\Local\Microsoft\Internet Explorer\UrlBlock\urlblock_635838931589367267.bin [63888] O61 - LFC: 2015/11/22 20:16:24 A . (..) -- C:\Users\Olivier\AppData\Local\Mail.Ru\mrkeeper.exe [1448152] ---\\ Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe © O67 - Shell Spawning: <.cmd> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Ob.) -- C:\Windows\System32\eventvwr.exe © O67 - Shell Spawning: <.exe> [HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.js> [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe © O67 - Shell Spawning: <.reg> [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe © O67 - Shell Spawning: <.scr> [HKLM\..\open\Command] (...) -- "%1" /S O67 - Shell Spawning: <.html> [HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe © ---\\ Menu de démarrage Internet (8) - 0s O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe © O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe © O68 - StartMenuInternet: [HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe © ---\\ Recherche d'infection sur les navigateurs (6) - 6s O69 - SBI: prefs.js [Olivier - 4og4kkpt.default] user_pref("extensions.fvd_single.enable_superfish", true); =>PUP.Optional.SpecialSavings O69 - SBI: prefs.js [Olivier - 4og4kkpt.default] user_pref("extensions.fvd_single.superfish_id", "0DABA9B3-5758-4037-AF6A-9A921BA6C78F"); =>PUP.Optional.SpecialSavings O69 - SBI: prefs.js [Olivier - 4og4kkpt.default] user_pref("extensions.{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.install-event-fired", true); =>Adware.Sambreel O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com/ O69 - SBI: SearchScopes [HKCU] {27916596-3ADE-4A11-B279-BEAF6C5A4612} - (Google) - http://www.google.com/ O69 - SBI: SearchScopes [HKCU] {FFEBBF0A-C22C-4172-89FF-45215A135AC7} [DefaultScope] - (Поиск@Mail.Ru) - http://go.mail.ru/ ---\\ Enumère les services démarrés par Svchost (42) - 0s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\WINDOWS\System32\certprop.dll [192000] © O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de ca.) -- C:\Windows\System32\certprop.dll [192000] © O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [283136] © O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [1335296] © O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\IKEEXT.DLL [954368] © O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur u.) -- C:\Windows\System32\iphlpsvc.dll [954880] © O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secon.) -- C:\Windows\System32\seclogon.dll [31232] © O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [93696] © O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [151040] © O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [106496] © O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1008640] © O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [226304] © O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [133120] © O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [324608] © O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à.) -- C:\Windows\System32\SessEnv.dll [371200] © O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [95744] © O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Service de compte Microsoft®.) -- C:\Windows\System32\wlidsvc.dll [2093056] © O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\System32\dcpsvc.dll [196096] © O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Service Assistant Connectivité réseau Micro.) -- C:\Windows\System32\NcaSvc.dll [167424] © O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Service Configuration du réseau.) -- C:\Windows\System32\NetSetupSvc.dll [187392] © O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’.) -- C:\Windows\System32\rasauto.dll [106496] © O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire des connexions d’accès à dista.) -- C:\Windows\System32\rasmans.dll [679936] © O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [497152] © O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements systèm.) -- C:\Windows\System32\Sens.dll [72192] © O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à.) -- C:\Windows\System32\ipnathlp.dll [452608] © O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM.) -- C:\Windows\System32\tapisrv.dll [311808] © O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Up.) -- C:\Windows\System32\wuaueng.dll [2236416] © O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière.) -- C:\Windows\System32\qmgr.dll [1168896] © O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [593920] © O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\System32\dmwappushsvc.dll [63488] © O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1149440] © O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\System32\XboxNetApiSvc.dll [1019392] © O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Mettre à jour la session Orchestrator Core.) -- C:\Windows\System32\usocore.dll [343040] © O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [713216] © O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Service de géolocalisation.) -- C:\Windows\System32\lfsvc.dll [27136] © O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - DLL Windows Management Service.) -- C:\Windows\System32\Windows.Internal.Management.dll [267776] © O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [918016] © O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\System32\RDXService.dll [1015808] © O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [359936] © O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Gestionnaire d’installation de périphérique.) -- C:\Windows\System32\DeviceSetupManager.dll [237568] © O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [58368] © O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Service Installation de logiciels.) -- C:\Windows\System32\appmgmts.dll [200192] © ---\\ Liste des exceptions du parefeu Windows (4) - 1s O87 - FAEL: "UDP Query User{5355295D-50B8-403E-B2F6-559AFEBA51F4}C:\program files (x86)\synology\assistant\dsassistant.exe" [In-None-P17-TRUE] .(...) -- C:\program files (x86)\synology\assistant\dsassistant.exe O87 - FAEL: "TCP Query User{FDA2C7C7-FD1F-4DE8-A35D-C4E0DEC48F8E}C:\program files (x86)\synology\assistant\dsassistant.exe" [In-None-P6-TRUE] .(...) -- C:\program files (x86)\synology\assistant\dsassistant.exe O87 - FAEL: "{72B76BA9-160F-4F8F-9797-BB218EABF287}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe O87 - FAEL: "{2E52B6A1-498F-437A-9A1B-F0154EC0005C}" [In-None-P17-TRUE] .(...) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ---\\ Enumère les codes produits des logiciels (1) - 1s O90 - PUC: "A233CACC4B7EE7544BC19DF2C6BB1311" . (.Flash Update Installer.) =>PUP.Optional.FlashUpdate ---\\ Services non Microsoft (SR=Démarré,SS=Stoppé) (32) - 12s SR - Auto [28/10/2015] [ 82128] Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe © SS - Demand [11/11/2015] [ 269000] Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe © SR - Auto [12/10/2015] [ 94888] ADU Service (Nokia Software Recovery Tool) (ADUServiceNSRT) . (...) - C:\Program Files (x86)\Common Files\Microsoft\Care Suite\ADUService\ADUService.exe SR - Auto [03/09/2014] [ 1243344] CAM Service (CAMService) . (.Intel® Corporation.) - C:\Program Files\Intel\CAM\bin\CAMService.exe © SS - Demand [17/07/2015] [ 283024] Intel(R) Content Protection HECI Service (cphs) . (.Intel Corporation.) - C:\Windows\SysWOW64\IntelCpHeciSvc.exe © SS - Auto [12/10/2015] [ 136048] Service Mise à jour Dropbox (dbupdate) (dbupdate) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe © SS - Demand [12/10/2015] [ 136048] Service Mise à jour Dropbox (dbupdatem) (dbupdatem) . (.Dropbox, Inc..) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe © SR - Auto [08/04/2015] [ 136576] EPSON V3 Service4(05) (EPSON_PM_RPCV4_05) . (.SEIKO EPSON CORPORATION.) - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE © SS - Auto [18/09/2015] [ 144200] Service Google Update (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SS - Demand [18/09/2015] [ 144200] Service Google Update (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe © SR - Auto [07/08/2013] [ 15720] Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe © SS - Demand [14/11/2005] [ 69632] InstallDriver Table Manager (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe © SR - Auto [17/07/2015] [ 351120] Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) . (.Intel Corporation.) - C:\Windows\System32\igfxCUIService.exe © SR - Auto [27/08/2013] [ 747520] Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe © SS - Demand [27/08/2013] [ 828376] Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe © SR - Auto [23/09/2013] [ 155448] Intel(R) Wireless Bluetooth(R) 4.0 Radio Management (Intel(R) Wireless Bluetooth(R) 4.0 Radio Management) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe © SR - Auto [01/01/2000] [ 169432] Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe © SR - Auto [01/01/2000] [ 390616] Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe © SR - Auto [05/10/2015] [ 1513784] (MBAMScheduler) . (.Malwarebytes.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe © SR - Auto [05/10/2015] [ 1135416] (MBAMService) . (.Malwarebytes.) - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe © SS - Demand [26/08/2015] [ 149160] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe © SR - Auto [03/07/2015] [ 324760] NitroPDFDriverCreatorReadSpool10 (NitroDriverReadSpool10) . (.Nitro PDF Software.) - C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe © SR - Auto [03/07/2015] [ 418968] NitroUpdateService (NitroUpdateService) . (...) - C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe SR - Auto [02/02/2015] [ 971968] Service KMSELDI (Service KMSELDI) . (.@ByELDI.) - C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico SR - Auto [11/09/2015] [ 5702416] TeamViewer 10 (TeamViewer) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe © SR - Auto [05/02/2015] [ 248736] UsbClientService (UsbClientService) . (...) - C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe SR - Auto [03/11/2015] [ 87744] VMware Authorization Service (VMAuthdService) . (.VMware, Inc..) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe © SR - Auto [03/11/2015] [ 359104] VMware DHCP Service (VMnetDHCP) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnetdhcp.exe © SR - Auto [21/10/2015] [ 915648] VMware USB Arbitration Service (VMUSBArbService) . (.VMware, Inc..) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe © SR - Auto [03/11/2015] [ 438464] VMware NAT Service (VMware NAT Service) . (.VMware, Inc..) - C:\Windows\SysWOW64\vmnat.exe © SS - Demand [03/11/2015] [12731584] VMware Workstation Server (VMwareHostd) . (...) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ---\\ Scan Additionnel (17) - 0s HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1 =>HackTool.KMSpico HKLM\SOFTWARE\Wow6432Node\ee480a2b-b3ce-acd0-c1a7-bcdecce57714 =>PUP.Optional.CrossRider HKLM\SOFTWARE\Wow6432Node\PIP =>Toolbar.Ask HKCU\SOFTWARE\APN PIP =>PUP.Optional.Conduit HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI =>HackTool.KMSpico C:\Program Files\KMSpico\Service_KMS.exe =>HackTool.KMSpico C:\Program Files\KMSpico\AutoPico.exe =>HackTool.KMSpico C:\WINDOWS\System32\Tasks\AutoPico Daily Restart =>HackTool.KMSpico C:\Users\Olivier\AppData\Roaming\Mozilla\Firefox\Profiles\4og4kkpt.default\extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi =>Adware.Sambreel C:\Program Files (x86)\CutTHEPrrice =>PUP.Optional.Multiplug C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS C:\Users\Olivier\AppData\Roaming\Tencent =>PUP.Optional.TencentAddressBar C:\Users\Olivier\AppData\Local\StormFall =>PUP.Optional.StormFall C:\WINDOWS\Prefetch\DRIVERREVIVER.EXE-0E603A48.pf =>PUP.Optional.DriverReviver HKLM\Software\Classes\Installer\Products\A233CACC4B7EE7544BC19DF2C6BB1311 =>PUP.Optional.FlashUpdate HKLM\Software\Classes\Installer\Features\A233CACC4B7EE7544BC19DF2C6BB1311 =>PUP.Optional.FlashUpdate ---\\ Récapitulatif des éléments trouvés sur votre station (12) - 0s http://www.nicolascoolman.fr/?p=989 =>HackTool.KMSpico http://www.nicolascoolman.fr/?p=180 =>PUP.Optional.CrossRider http://www.nicolascoolman.fr/?p=235 =>Toolbar.Ask http://www.nicolascoolman.fr/?p=210 =>PUP.Optional.Conduit http://www.nicolascoolman.fr/?p=4664 =>Adware.Sambreel http://www.nicolascoolman.fr/?p=1402 =>PUP.Optional.Multiplug http://www.nicolascoolman.fr/?p=1804 =>HackTool.AutoKMS http://www.nicolascoolman.fr/?p=368 =>PUP.Optional.TencentAddressBar http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.StormFall http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.DriverReviver http://www.nicolascoolman.fr/?p=710 =>PUP.Optional.SpecialSavings http://www.nicolascoolman.fr/?p=4664 =>PUP.Optional.FlashUpdate ~ End of the scan, 44489 items in 82 seconds (1182)(0)